This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Unknown virus

24 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey all, I am trying to figure out what is going on exactly with my pc (windows xp). All the sudden I was unable to open many programs and my web browsers are hijacked. I have tried running all my antivirus software but none will open. I tried fresh installs but still nothing. I even tried to install new programs but no success. I've tried everything I can think of but nothing seems to work. I attempted to create a hijackthis log but to no avail. Hopefully someone will know what is happening. Thanks in advance.
Hi there,

Welcome to WTT.


OK firstly, I need you to print out each post I make so that you can refer to it while we fix your computer. This is because there will be times when you are unable to be online to read my instructions, and I will want you to do everything very carefully. I also need you to follow my instructions in the order that they are given. If however, you cannot carry out one of them, please continue on with the next and let me know what you were unsuccessful with.

Next, I would like to make sure that you can view hidden files and folders;
  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View tab.
  • Under the Hidden files and folders heading SELECT Show hidden files and folders.
  • UNCHECK the Hide protected operating system files (recommended) option.
  • UNCHECK the Hide extensions for known file types option.
  • Click Yes to confirm.
  • Click OK.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


Please download ATF Cleaner by Atribune.Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double-click gmer.exe. The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised by a trained Security Analyst

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.
Post the contents of GMER.txt in your next reply.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done, DDS.txt will open.
  • Click Yes at the next prompt for Optional Scan.
  • Save both reports to your desktop.
Please include the contents of the following in your next reply:
  • DDS.txt
  • Attach.txt
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


So in your next reply, please include the following logs:
  • The contents of GMER.txt
  • The contents of both DDS.txt and Attach.txt
Please make a separate post for each log.

Regards,
RatHat
I ran all three programs. I was unable to get gmer to work. It will unzip but not open so I was unable to get a log. DDS (Version 1.1.0) - NTFSx86 Run by [removed] at 11:14:21.50 on Sat 01/03/2009 Internet Explorer: 6.0.2900.2180 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.383.125 [GMT -5:00] AV: Norton Internet Security *On-access scanning enabled* (Updated) AV: avast! antivirus 4.8.1296 [VPS 090103-0] *On-access scanning disabled* (Updated) ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\WINDOWS\sm56hlpr.exe C:\WINDOWS\ALCXMNTR.EXE C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\WINDOWS\system32\ps2.exe c:\windows\system\hpsysdrv.exe C:\Program Files\Java\jre1.5.0\bin\jusched.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\Documents and Settings\Compaq_Owner\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.yahoo.com/ uSearch Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=presario&pf=desktop uSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=presario&pf=desktop uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=presario&pf=desktop uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=presario&pf=desktop mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=presario&pf=desktop mDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=presario&pf=desktop mSearch Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=presario&pf=desktop mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=presario&pf=desktop mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=presario&pf=desktop uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=presario&pf=desktop uSearchURL,(Default) = hxxp://www.google.com/keyword/%s mSearchAssistant = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=presario&pf=desktop BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File TB: {DE9C389F-3316-41A7-809B-AA305ED9D922} - No File uRun: [PeerGuardian] c:\program files\peerguardian2\pg2.exe uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe" mRun: [HPBootOp] "c:\program files\hewlett-packard\hp boot optimizer\HPBootOp.exe" /run mRun: [SMSERIAL] sm56hlpr.exe mRun: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe mRun: [AlcxMonitor] ALCXMNTR.EXE mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [SpySweeper] "c:\program files\webroot\spy sweeper\SpySweeper.exe" /startintray IE: Add To Compaq Organize… - c:\progra~1\hewlet~1\compaq~1\bin/module.main/favorites\ie_add_to.html IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office11\EXCEL.EXE/3000 IE: {E2D4D26B-0180-43a4-B05F-462D6D54C789} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\iebutton\support.htm IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_09\bin\ssv.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office11\REFIEBAR.DLL IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: WRNotifier - WRLogonNTF.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\compaq~1\applic~1\mozilla\firefox\profiles\k1fomxfs.default\ FF - prefs.js: browser.startup.homepage - www.yahoo.com ============= SERVICES / DRIVERS =============== R0 SSI;SSI;c:\windows\system32\drivers\ssi.sys [2008-12-16 78336] R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-4-9 111184] R4 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-4-9 20560] R4 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2007-8-15 155160] R4 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2004-8-27 197752] R4 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSetMgr.exe [2004-8-27 164984] S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2007-8-15 254040] S3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2007-8-15 352920] S3 ccPwdSvc;Symantec Password Validation;c:\program files\common files\symantec shared\ccPwdSvc.exe [2004-8-27 78968] =============== Created Last 30 ================ 2009-01-02 14:54 116,224 a——- c:\windows\system32\dllcache\xrxwiadr.dll 2009-01-02 14:54 23,040 a——- c:\windows\system32\dllcache\xrxwbtmp.dll 2009-01-02 14:54 17,408 a——- c:\windows\system32\dllcache\xrxscnui.dll 2009-01-02 14:54 27,648 a——- c:\windows\system32\dllcache\xrxftplt.exe 2009-01-02 14:54 4,608 a——- c:\windows\system32\dllcache\xrxflnch.exe 2009-01-02 14:52 19,551 a——- c:\windows\system32\dllcache\watv02nt.sys 2009-01-02 14:51 7,556 a——- c:\windows\system32\dllcache\usroslba.sys 2009-01-02 14:50 211,968 a——- c:\windows\system32\dllcache\um54scan.dll 2009-01-02 14:49 230,912 a——- c:\windows\system32\dllcache\tosdvd03.sys 2009-01-02 14:48 30,688 a——- c:\windows\system32\dllcache\sym_u3.sys 2009-01-02 14:47 24,660 a——- c:\windows\system32\dllcache\spxupchk.dll 2009-01-02 14:46 6,784 a——- c:\windows\system32\dllcache\smbhc.sys 2009-01-02 14:45 161,568 a——- c:\windows\system32\dllcache\sgsmusb.sys 2009-01-02 14:44 75,392 a——- c:\windows\system32\dllcache\s3savmxm.sys 2009-01-02 14:43 30,720 a——- c:\windows\system32\dllcache\rthwcls.sys 2009-01-02 14:42 45,312 a——- c:\windows\system32\dllcache\ql12160.sys 2009-01-02 14:41 19,840 a——- c:\windows\system32\dllcache\philtune.sys 2009-01-02 14:40 25,216 a——- c:\windows\system32\dllcache\ovsound2.sys 2009-01-02 14:39 51,552 a——- c:\windows\system32\dllcache\ntgrip.sys 2009-01-02 14:38 33,088 a——- c:\windows\system32\dllcache\n9i128v2.sys 2009-01-02 14:37 1,875,968 a——- c:\windows\system32\dllcache\msir3jp.lex 2009-01-02 14:36 58,880 a——- c:\windows\system32\dllcache\m3092dc.dll 2009-01-02 14:35 45,568 a——- c:\windows\system32\dllcache\kdsui.dll 2009-01-02 14:34 307,257 a——- c:\windows\system32\dllcache\imjpdct.exe 2009-01-02 14:33 8,192 a——- c:\windows\system32\dllcache\i2omgmt.sys 2009-01-02 14:32 68,608 a——- c:\windows\system32\dllcache\hpgt53tk.dll 2009-01-02 14:31 454,912 a——- c:\windows\system32\dllcache\fxusbase.sys 2009-01-02 14:30 347,550 a——- c:\windows\system32\dllcache\es56tpi.sys 2009-01-02 14:29 20,992 a——- c:\windows\system32\dllcache\dshowext.ax 2009-01-02 14:28 78,848 a——- c:\windows\system32\dllcache\dayi.ime 2009-01-02 14:27 46,108 a——- c:\windows\system32\dllcache\cben5.sys 2009-01-02 14:26 23,552 a——- c:\windows\system32\dllcache\atixbar.sys 2009-01-02 14:25 231,552 a——- c:\windows\system32\dllcache\ac97ali.sys 2009-01-02 14:25 462,848 a——- c:\windows\system32\dllcache\a3dapi.dll 2009-01-02 14:25 98,304 a——- c:\windows\system32\dllcache\a3d.dll 2009-01-02 14:25 23,552 a——- c:\windows\system32\dllcache\abp480n5.sys 2009-01-02 14:25 38,400 a——- c:\windows\system32\dllcache\8514a.dll 2009-01-02 14:25 48,128 a——- c:\windows\system32\dllcache\61883.sys 2009-01-02 14:25 689,216 a——- c:\windows\system32\dllcache\3dfxvs.dll 2009-01-02 14:25 148,352 a——- c:\windows\system32\dllcache\3dfxvsm.sys 2009-01-02 14:25 12,288 a——- c:\windows\system32\dllcache\4mmdat.sys 2009-01-02 14:25 762,780 a——- c:\windows\system32\dllcache\3cwmcru.sys 2009-01-02 14:25 11,264 a——- c:\windows\system32\dllcache\1394vdbg.sys 2009-01-02 14:25 66,048 a——- c:\windows\system32\dllcache\s3legacy.dll 2008-12-16 23:06 102,912 a——- c:\windows\system32\islzma.dll 2008-12-16 23:06 78,336 a——- c:\windows\system32\drivers\ssi.sys 2008-12-16 23:06 –d—– c:\program files\Webroot 2008-12-16 23:06 –d—– c:\docume~1\compaq~1\applic~1\Webroot ==================== Find3M ==================== 2008-12-31 20:08 9,476 a——- c:\docume~1\compaq~1\applic~1\wklnhst.dat 2008-12-12 12:27 3,067,392 a——- c:\windows\system32\dllcache\mshtml.dll 2008-11-10 12:05 18,699 a——- c:\windows\system32\~.exe 2008-10-24 06:10 453,632 a——- c:\windows\system32\dllcache\mrxsmb.sys 2008-10-23 08:01 283,648 a——- c:\windows\system32\gdi32.dll 2008-10-23 08:01 283,648 a——- c:\windows\system32\dllcache\gdi32.dll 2008-10-16 14:13 1,809,944 a——- c:\windows\system32\dllcache\wuaueng.dll 2008-10-16 14:13 202,776 a——- c:\windows\system32\dllcache\wuweb.dll 2008-10-16 14:12 323,608 a——- c:\windows\system32\dllcache\wucltui.dll 2008-10-16 14:12 561,688 a——- c:\windows\system32\dllcache\wuapi.dll 2008-10-16 14:09 92,696 a——- c:\windows\system32\dllcache\cdm.dll 2008-10-16 14:09 51,224 a——- c:\windows\system32\dllcache\wuauclt.exe 2008-10-16 14:08 34,328 a——- c:\windows\system32\dllcache\wups.dll 2008-10-15 11:57 332,800 a——- c:\windows\system32\dllcache\netapi32.dll 2008-10-15 09:18 18,432 a——- c:\windows\system32\dllcache\iedw.exe 2008-05-15 16:48 87,608 a——- c:\docume~1\compaq~1\applic~1\inst.exe 2008-05-15 16:48 47,360 a——- c:\docume~1\compaq~1\applic~1\pcouffin.sys 2008-01-04 16:57 32 a——- c:\docume~1\alluse~1\applic~1\ezsid.dat ============= FINISH: 11:15:04.57 ===============
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Version 1.0) Microsoft Windows XP Home Edition Boot Device: \Device\HarddiskVolume2 Install Date: 8/10/2005 5:08:32 PM System Uptime: 1/3/2009 10:58:58 AM (1 hours ago) Motherboard: ASUSTek Computer INC. | | Salmon Processor: AMD Sempron™ Processor 3000+ | Socket 754 | 1808/200mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 143 GiB total, 53.649 GiB free. D: is FIXED (FAT32) - 6 GiB total, 0.979 GiB free. E: is CDROM () F: is Removable G: is Removable H: is Removable I: is Removable J: is Removable ==== Disabled Device Manager Items ============= Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318} Description: Integrated 10/100 Ethernet Controller Device ID: ROOT\NET\0000 Manufacturer: IBM Name: Integrated 10/100 Ethernet Controller PNP Device ID: ROOT\NET\0000 Service: SISNIC ==== System Restore Points =================== RP358: 1/3/2009 11:11:41 AM - System Checkpoint ==== Installed Programs ====================== avast! Antivirus ==== Event Viewer Messages From Past Week ======== 12/27/2008 11:27:29 AM, error: System Error [1003] - Error code 1000000a, parameter1 00001018, parameter2 00000002, parameter3 00000000, parameter4 804f3460. 12/27/2008 11:27:19 AM, error: System Error [1003] - Error code 1000000a, parameter1 00000018, parameter2 00000002, parameter3 00000000, parameter4 804f3460. 12/27/2008 10:56:39 AM, error: Service Control Manager [7000] - The Webroot Spy Sweeper Engine service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 12/27/2008 10:56:39 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Webroot Spy Sweeper Engine service to connect. 12/31/2008 7:38:40 PM, error: System Error [1003] - Error code 1000000a, parameter1 02750032, parameter2 00000002, parameter3 00000000, parameter4 804f3460. 1/2/2009 2:07:07 PM, error: Service Control Manager [7034] - The Machine Debug Manager service terminated unexpectedly. It has done this 1 time(s). 1/2/2009 3:16:32 PM, error: Print [19] - Sharing printer failed + 1722, Printer Microsoft Office Document Image Writer share name Printer. 1/2/2009 4:19:46 PM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning. 1/2/2009 4:19:46 PM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. 1/2/2009 4:19:46 PM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning. 1/2/2009 4:19:46 PM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning. 1/2/2009 4:19:46 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Aavmker4 AFD AmdK8 ASPI32 aswSP aswTdi Fips IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss SYMTDI Tcpip 1/2/2009 4:22:07 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E} 1/2/2009 4:22:11 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 1/3/2009 11:11:41 AM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume. 1/2/2009 2:25:12 PM, information: Windows File Protection [64016] - Windows File Protection file scan was started. 1/2/2009 2:25:19 PM, information: Windows File Protection [64020] - Windows File Protection scan found that the system file c:\windows\help\apps.chm has a bad signature. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1. 1/2/2009 2:54:19 PM, information: Windows File Protection [64017] - Windows File Protection file scan completed successfully. ==== End Of File ===========================
Looks like you have two Anti Virus programs running, Norton Symantec and Avast. Please uninstall one of these as two AV's will lead to conflicts. When done, disable Spy Sweeper, then try to run GMER again.
That is very strange. I know my way around a computer fairly well and when I got this computer a few years ago Norton was the first program I got rid of, and I haven't reinstalled it since. However it shows up in my add/remove programs. I tried to remove it but the computer no longer lets me uninstall any of the programs listed. Spysweeper is also not running. I still couldn't get GMER to run. I'm not sure if it's important or not but some programs run and some don't. And, no new programs are allowed to be installed either.
This is a strange one!

Lets see if we can get this to work:

Please download DrWeb-CureIt & save it to your desktop. DO NOT perform a scan yet.

Reboot your computer in "SAFE MODE" using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".

Scan with DrWeb-CureIt as follows:
  • Double-click on drweb-cureit.exe to start the program. An "Express Scan of your PC" notice will appear.
  • Under "Start the Express Scan Now", Click "OK" to start. This is a short scan that will scan the files currently running in memory and when something is found, click the Yes button when it asks you if you want to cure it.
  • Once the short scan has finished, Click Options > Change settings
  • Choose the "Scan tab" and UNcheck "Heuristic analysis"
  • Back at the main window, click "Select drives" (a red dot will show which drives have been chosen)
  • Then click the "Start/Stop Scanning" button (green arrow on the right) and the scan will start.
  • When done, a message will be displayed at the bottom advising if any viruses were found.
  • Click "Yes to all" if it asks if you want to cure/move the file.
  • When the scan has finished, look if you can see the icon next to the files found. If so, click it, then click the next icon right below and select "Move incurable".
    (This will move it to the C:\Documents and Settings\userprofile\DoctorWeb\Quarantine folder if it can't be cured)
  • Next, in the Dr.Web CureIt menu on top, click file and choose save report list.
  • Save the DrWeb.csv report to your desktop.
  • Exit Dr.Web Cureit when done.
  • Important! Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web in your next reply. (You can use Notepad to open the DrWeb.cvs report)
Hi there,

Lets hold off on DrWeb for the moment and see if we can make another check to see if you have a rootkit hidden in there.

Copy (Ctrl +C) and paste (Ctrl +V) the text in the code box below to Notepad.

@echo off
Copy /y gmer.exe ark.exe
Start ark.exe

Save it into the gmer folder as File name: ark.cmd
Save as type: All Files

Once done, double click ark.cmd to run it.

This should start GMER, follow the steps I have outlined earlier to save a log file, then post me the contents in your next reply.
Here is the log file. It said that I possibly have 2 rootkits.




GMER 1.0.14.14536 - http://www.gmer.net
Rootkit scan 2009-01-04 10:45:29
Windows 5.1.2600 Service Pack 2


—- System - GMER 1.0.14 —-

SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xB1C0E576]
SSDT 82FC4500 ZwConnectPort
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xB1C0E432]
SSDT SSI.SYS (SpySweeper SSI Driver/Webroot Software (www.webroot.com)) ZwCreateProcess [0xF73963CE]
SSDT SSI.SYS (SpySweeper SSI Driver/Webroot Software (www.webroot.com)) ZwCreateProcessEx [0xF739656E]
SSDT SSI.SYS (SpySweeper SSI Driver/Webroot Software (www.webroot.com)) ZwDeleteKey [0xF7394E94]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xB1C0E910]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xB1C0E00A]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xB1C0E50C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xB1C0DF4A]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xB1C0DFAE]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xB1C0E62C]
SSDT SSI.SYS (SpySweeper SSI Driver/Webroot Software (www.webroot.com)) ZwRenameKey [0xF739500A]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xB1C0E5EC]
SSDT SSI.SYS (SpySweeper SSI Driver/Webroot Software (www.webroot.com)) ZwSetInformationKey [0xF73951DA]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xB1C0E76C]

Code E1A800A0 ZwEnumerateKey
Code E1A810D8 ZwFlushInstructionCache
Code B1EA7EAB pIofCallDriver

—- Kernel code sections - GMER 1.0.14 —-

PAGE ntkrnlpa.exe!ZwFlushInstructionCache 805AAC4A 5 Bytes JMP E1A810DC
PAGE ntkrnlpa.exe!ZwEnumerateKey 80619752 5 Bytes JMP E1A800A4
? System32\Drivers\hiber_WMILIB.SYS The system cannot find the path specified. !

—- User code sections - GMER 1.0.14 —-

.text C:\WINDOWS\Explorer.EXE[120] WS2_32.dll!connect 71AB406A 5 Bytes JMP 00AA000A
.text C:\WINDOWS\Explorer.EXE[120] WS2_32.dll!send 71AB428A 5 Bytes JMP 00AC000A
.text C:\WINDOWS\Explorer.EXE[120] WS2_32.dll!closesocket 71AB9639 5 Bytes JMP 00AB000A

—- User IAT/EAT - GMER 1.0.14 —-

IAT C:\WINDOWS\system32\services.exe[612] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 00390002
IAT C:\WINDOWS\system32\services.exe[612] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 00390000
IAT C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe[1764] @ C:\WINDOWS\system32\user32.dll [KERNEL32.dll!CreateThread] [0042C5E8] C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe (Spy Sweeper SDK/Webroot Software, Inc.)
IAT C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe[1764] @ C:\WINDOWS\system32\advapi32.dll [KERNEL32.dll!CreateThread] [0042C5E8] C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe (Spy Sweeper SDK/Webroot Software, Inc.)
IAT C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe[1764] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateThread] [0042C5E8] C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe (Spy Sweeper SDK/Webroot Software, Inc.)
IAT C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe[1764] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateThread] [0042C5E8] C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe (Spy Sweeper SDK/Webroot Software, Inc.)
IAT C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe[1764] @ C:\WINDOWS\system32\wininet.dll [KERNEL32.dll!CreateThread] [0042C5E8] C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe (Spy Sweeper SDK/Webroot Software, Inc.)
IAT C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe[1764] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!CreateThread] [0042C5E8] C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe (Spy Sweeper SDK/Webroot Software, Inc.)
IAT C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe[1764] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateThread] [0042C5E8] C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe (Spy Sweeper SDK/Webroot Software, Inc.)
IAT C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe[1764] @ C:\WINDOWS\system32\shell32.dll [KERNEL32.dll!CreateThread] [0042C5E8] C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe (Spy Sweeper SDK/Webroot Software, Inc.)
IAT C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe[1764] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!CreateThread] [0042C5E8] C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe (Spy Sweeper SDK/Webroot Software, Inc.)
IAT C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe[1764] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!CreateThread] [0042C5E8] C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe (Spy Sweeper SDK/Webroot Software, Inc.)

—- Devices - GMER 1.0.14 —-

AttachedDevice \FileSystem\Ntfs \Ntfs SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)

Device \Driver\Tcpip \Device\Ip SSI.SYS (SpySweeper SSI Driver/Webroot Software (www.webroot.com))

AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip aswRdr.SYS (avast! TDI RDR Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

Device \Driver\Tcpip \Device\Tcp SSI.SYS (SpySweeper SSI Driver/Webroot Software (www.webroot.com))

AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp aswRdr.SYS (avast! TDI RDR Driver/ALWIL Software)

Device \Driver\Tcpip \Device\Udp SSI.SYS (SpySweeper SSI Driver/Webroot Software (www.webroot.com))

AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp aswRdr.SYS (avast! TDI RDR Driver/ALWIL Software)

Device \Driver\Tcpip \Device\RawIp SSI.SYS (SpySweeper SSI Driver/Webroot Software (www.webroot.com))

AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

Device \Driver\Tcpip \Device\IPMULTICAST SSI.SYS (SpySweeper SSI Driver/Webroot Software (www.webroot.com))

AttachedDevice \FileSystem\Fastfat \Fat SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)

—- Modules - GMER 1.0.14 —-

Module \systemroot\system32\drivers\TDSSmaxt.sys (*** hidden *** ) B1EA6000-B1EB8000 (73728 bytes)

—- Threads - GMER 1.0.14 —-

Thread 4:296 B1EA8D66

—- Services - GMER 1.0.14 —-

Service C:\WINDOWS\system32\drivers\TDSSmaxt.sys (*** hidden *** ) [SYSTEM] TDSSserv.sys <– ROOTKIT !!!

—- Registry - GMER 1.0.14 —-

Reg HKLM\SYSTEM\ControlSet001\Services\TDSSserv.sys
Reg HKLM\SYSTEM\ControlSet001\Services\TDSSserv.sys@start 1
Reg HKLM\SYSTEM\ControlSet001\Services\TDSSserv.sys@type 1
Reg HKLM\SYSTEM\ControlSet001\Services\TDSSserv.sys@imagepath \systemroot\system32\drivers\TDSSmaxt.sys
Reg HKLM\SYSTEM\ControlSet001\Services\TDSSserv.sys@group file system
Reg HKLM\SYSTEM\ControlSet001\Services\TDSSserv.sys\modules
Reg HKLM\SYSTEM\ControlSet001\Services\TDSSserv.sys\modules@TDSSserv \systemroot\system32\drivers\TDSSmaxt.sys
Reg HKLM\SYSTEM\ControlSet001\Services\TDSSserv.sys\modules@TDSSl \systemroot\system32\TDSSofxh.dll
Reg HKLM\SYSTEM\ControlSet001\Services\TDSSserv.sys\modules@tdssservers \systemroot\system32\TDSSosvd.dat
Reg HKLM\SYSTEM\ControlSet001\Services\TDSSserv.sys\modules@tdssmain \systemroot\system32\TDSSnrsr.dll
Reg HKLM\SYSTEM\ControlSet001\Services\TDSSserv.sys\modules@tdsslog \systemroot\system32\TDSSriqp.dll
Reg HKLM\SYSTEM\ControlSet001\Services\TDSSserv.sys\modules@tdssadw \systemroot\system32\TDSScfub.dll
Reg HKLM\SYSTEM\ControlSet001\Services\TDSSserv.sys\modules@tdssinit \systemroot\system32\TDSSfxmp.dll
Reg HKLM\SYSTEM\ControlSet001\Services\TDSSserv.sys\modules@tdssurls \systemroot\system32\TDSSnmxh.log
Reg HKLM\SYSTEM\ControlSet001\Services\TDSSserv.sys\modules@tdsspanels \systemroot\system32\TDSSsbhc.dll
Reg HKLM\SYSTEM\ControlSet001\Services\TDSSserv.sys\modules@tdsserrors \systemroot\system32\TDSSrhym.log
Reg HKLM\SYSTEM\ControlSet001\Services\TDSSserv.sys\modules@TDSSproc \systemroot\system32\TDSStkdv.log
Reg HKLM\SYSTEM\ControlSet002\Services\TDSSserv.sys
Reg HKLM\SYSTEM\ControlSet002\Services\TDSSserv.sys@start 1
Reg HKLM\SYSTEM\ControlSet002\Services\TDSSserv.sys@type 1
Reg HKLM\SYSTEM\ControlSet002\Services\TDSSserv.sys@imagepath \systemroot\system32\drivers\TDSSmaxt.sys
Reg HKLM\SYSTEM\ControlSet002\Services\TDSSserv.sys@group file system
Reg HKLM\SYSTEM\ControlSet002\Services\TDSSserv.sys\modules
Reg HKLM\SYSTEM\ControlSet002\Services\TDSSserv.sys\modules@TDSSserv \systemroot\system32\drivers\TDSSmaxt.sys
Reg HKLM\SYSTEM\ControlSet002\Services\TDSSserv.sys\modules@TDSSl \systemroot\system32\TDSSofxh.dll
Reg HKLM\SYSTEM\ControlSet002\Services\TDSSserv.sys\modules@tdssservers \systemroot\system32\TDSSosvd.dat
Reg HKLM\SYSTEM\ControlSet002\Services\TDSSserv.sys\modules@tdssmain \systemroot\system32\TDSSnrsr.dll
Reg HKLM\SYSTEM\ControlSet002\Services\TDSSserv.sys\modules@tdsslog \systemroot\system32\TDSSriqp.dll
Reg HKLM\SYSTEM\ControlSet002\Services\TDSSserv.sys\modules@tdssadw \systemroot\system32\TDSScfub.dll
Reg HKLM\SYSTEM\ControlSet002\Services\TDSSserv.sys\modules@tdssinit \systemroot\system32\TDSSfxmp.dll
Reg HKLM\SYSTEM\ControlSet002\Services\TDSSserv.sys\modules@tdssurls \systemroot\system32\TDSSnmxh.log
Reg HKLM\SYSTEM\ControlSet002\Services\TDSSserv.sys\modules@tdsspanels \systemroot\system32\TDSSsbhc.dll
Reg HKLM\SYSTEM\ControlSet002\Services\TDSSserv.sys\modules@tdsserrors \systemroot\system32\TDSSrhym.log
Reg HKLM\SYSTEM\ControlSet002\Services\TDSSserv.sys\modules@TDSSproc \systemroot\system32\TDSStkdv.log
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys@imagepath \systemroot\system32\drivers\TDSSmaxt.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys\modules@TDSSserv \systemroot\system32\drivers\TDSSmaxt.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys\modules@TDSSl \systemroot\system32\TDSSofxh.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys\modules@tdssservers \systemroot\system32\TDSSosvd.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys\modules@tdssmain \systemroot\system32\TDSSnrsr.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys\modules@tdsslog \systemroot\system32\TDSSriqp.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys\modules@tdssadw \systemroot\system32\TDSScfub.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys\modules@tdssinit \systemroot\system32\TDSSfxmp.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys\modules@tdssurls \systemroot\system32\TDSSnmxh.log
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys\modules@tdsspanels \systemroot\system32\TDSSsbhc.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys\modules@tdsserrors \systemroot\system32\TDSSrhym.log
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys\modules@TDSSproc \systemroot\system32\TDSStkdv.log
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\tdssdata
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\tdssdata@affid 62
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\tdssdata@subid v3av
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\tdssdata@control 0x09 0x19 0x1F 0x16 …
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\tdssdata@prov 10010
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\tdssdata@googleadserver pagead2.googlesyndication.com
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\tdssdata@flagged 1

—- EOF - GMER 1.0.14 —-
OK, now we've got it!

Please download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop

* Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix. If you are unsure of how to disable these programs, please refer to this page for details.
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it will produce a log for you. Please include the contents of C:\ComboFix.txt in your next reply.

Note: If you are unsure about anything, a very good Combofix tutorial can be found here.
I was running combofix but it was telling me that I am running a norton internet security scanner, something I didn't have but is now installed on my computer without a folder in "program files". I also ran spysweeper using the ark.exe method. It picked up the same trojan as gmer with 56 traces of it. I didn't make any changes though. Should I still run combofix anyway?
Please DO NOT try to run things other than what I ask you.

Please run Combofix as I have outlined above, and post me the log it produces. Please do not do anything else until I have seen the log, and can advise you what to do next.
Here is the log





ComboFix 09-01-02.01 - Compaq_Owner 2009-01-04 14:07:21.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.383.131 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\New Folder\ark.exe
AV: Norton Internet Security *On-access scanning enabled* (Updated)
AV: avast! antivirus 4.8.1296 [VPS 090103-0] *On-access scanning enabled* (Updated)
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Compaq_Owner\Application Data\inst.exe
c:\windows\k.txt
c:\windows\system32\~.exe
c:\windows\system32\au3305adc.dll
c:\windows\system32\av.exe
c:\windows\system32\drivers\TDSSmaxt.sys
c:\windows\system32\getwn32.dll
c:\windows\system32\TDSScfub.dll
c:\windows\system32\TDSSfxmp.dll
c:\windows\system32\TDSSnmxh.log
c:\windows\system32\TDSSnrsr.dll
c:\windows\system32\TDSSofxh.dll
c:\windows\system32\TDSSosvd.dat
c:\windows\system32\TDSSrhym.log
c:\windows\system32\TDSSriqp.dll
c:\windows\system32\TDSSsbhc.dll
c:\windows\system32\TDSStkdv.log
c:\windows\system32\wertyu.dll
D:\Autorun.inf

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_TDSSSERV.SYS
——-\Legacy_TDSSSERV.SYS


((((((((((((((((((((((((( Files Created from 2008-12-04 to 2009-01-04 )))))))))))))))))))))))))))))))
.

2009-01-03 21:02 . 2009-01-03 22:37 d——– c:\documents and settings\Compaq_Owner\DoctorWeb
2009-01-02 16:23 . 2005-05-16 17:37 d——– c:\documents and settings\Administrator\WINDOWS
2009-01-02 16:23 . 2005-05-16 18:01 d——– c:\documents and settings\Administrator\Application Data\Symantec
2009-01-02 16:23 . 2005-05-16 17:52 d——– c:\documents and settings\Administrator\Application Data\SampleView
2009-01-02 16:23 . 2005-05-16 17:57 d——– c:\documents and settings\Administrator\Application Data\InterMute
2009-01-02 16:23 . 2005-05-16 17:36 d——– c:\documents and settings\Administrator\Application Data\Apple Computer
2009-01-02 16:23 . 2009-01-04 11:32 d——– c:\documents and settings\Administrator
2009-01-02 14:54 . 2004-08-04 00:56 116,224 –a—— c:\windows\system32\dllcache\xrxwiadr.dll
2009-01-02 14:54 . 2001-08-17 22:37 27,648 –a—— c:\windows\system32\dllcache\xrxftplt.exe
2009-01-02 14:54 . 2001-08-17 22:36 23,040 –a—— c:\windows\system32\dllcache\xrxwbtmp.dll
2009-01-02 14:54 . 2001-08-17 22:36 17,408 –a—— c:\windows\system32\dllcache\xrxscnui.dll
2009-01-02 14:54 . 2001-08-17 22:37 4,608 –a—— c:\windows\system32\dllcache\xrxflnch.exe
2009-01-02 14:52 . 2001-08-17 13:28 765,884 –a—— c:\windows\system32\dllcache\usrti.sys
2009-01-02 14:51 . 2001-08-17 13:28 794,654 –a—— c:\windows\system32\dllcache\usr1801.sys
2009-01-02 14:50 . 2001-08-17 22:36 525,568 –a—— c:\windows\system32\dllcache\tridxp.dll
2009-01-02 14:49 . 2004-08-04 07:00 571,392 –a—— c:\windows\system32\dllcache\tintlgnt.ime
2009-01-02 14:48 . 2001-08-17 12:18 285,760 –a—— c:\windows\system32\dllcache\stlnata.sys
2009-01-02 14:47 . 2001-08-17 14:56 147,200 –a—— c:\windows\system32\dllcache\smidispb.dll
2009-01-02 14:46 . 2004-08-03 22:41 404,990 –a—— c:\windows\system32\dllcache\slntamr.sys
2009-01-02 14:45 . 2001-08-17 22:36 495,616 –a—— c:\windows\system32\dllcache\sblfx.dll
2009-01-02 14:44 . 2004-08-04 00:56 397,056 –a—— c:\windows\system32\dllcache\s3gnb.dll
2009-01-02 14:43 . 2001-08-17 13:28 899,146 –a—— c:\windows\system32\dllcache\r2mdkxga.sys
2009-01-02 14:42 . 2004-08-04 07:00 482,304 –a—— c:\windows\system32\dllcache\pintlgnt.ime
2009-01-02 14:41 . 2004-08-04 00:56 259,328 –a—— c:\windows\system32\dllcache\perm3dd.dll
2009-01-02 14:40 . 2004-08-04 00:56 4,274,816 –a—— c:\windows\system32\dllcache\nv4_disp.dll
2009-01-02 14:39 . 2004-08-03 22:31 132,695 –a—— c:\windows\system32\dllcache\netwlan5.sys
2009-01-02 14:38 . 2004-08-04 00:56 1,737,856 –a—— c:\windows\system32\dllcache\mtxparhd.dll
2009-01-02 14:37 . 2004-08-04 07:00 1,875,968 –a—— c:\windows\system32\dllcache\msir3jp.lex
2009-01-02 14:36 . 2004-08-04 07:00 1,158,818 –a—— c:\windows\system32\dllcache\korwbrkr.lex
2009-01-02 14:35 . 2004-08-04 07:00 471,102 –a—— c:\windows\system32\dllcache\imskdic.dll
2009-01-02 14:34 . 2004-08-04 07:00 811,064 –a—— c:\windows\system32\dllcache\imjp81k.dll
2009-01-02 14:33 . 2004-08-04 07:00 13,463,552 –a—— c:\windows\system32\dllcache\hwxjpn.dll
2009-01-02 14:32 . 2001-08-17 14:56 1,733,120 –a—— c:\windows\system32\dllcache\g400d.dll
2009-01-02 14:31 . 2001-08-17 12:15 455,680 –a—— c:\windows\system32\dllcache\fus2base.sys
2009-01-02 14:30 . 2001-08-17 13:28 634,134 –a—— c:\windows\system32\dllcache\el656ct5.sys
2009-01-02 14:29 . 2001-08-17 12:14 952,007 –a—— c:\windows\system32\dllcache\diwan.sys
2009-01-02 14:28 . 2004-08-04 07:00 1,677,824 –a—— c:\windows\system32\dllcache\chsbrkr.dll
2009-01-02 14:27 . 2001-08-17 13:28 871,388 –a—— c:\windows\system32\dllcache\bcmdm.sys
2009-01-02 14:26 . 2004-08-04 00:56 1,888,992 –a—— c:\windows\system32\dllcache\ati3duag.dll
2009-01-02 14:25 . 2001-08-17 13:28 762,780 –a—— c:\windows\system32\dllcache\3cwmcru.sys
2009-01-02 14:25 . 2001-08-17 14:55 689,216 –a—— c:\windows\system32\dllcache\3dfxvs.dll
2009-01-02 14:25 . 2001-08-17 22:36 462,848 –a—— c:\windows\system32\dllcache\a3dapi.dll
2009-01-02 14:25 . 2004-08-03 22:32 231,552 –a—— c:\windows\system32\dllcache\ac97ali.sys
2009-01-02 14:25 . 2001-08-17 12:48 148,352 –a—— c:\windows\system32\dllcache\3dfxvsm.sys
2009-01-02 14:25 . 2001-08-17 22:36 98,304 –a—— c:\windows\system32\dllcache\a3d.dll
2009-01-02 14:25 . 2001-08-17 14:56 66,048 –a—— c:\windows\system32\dllcache\s3legacy.dll
2009-01-02 14:25 . 2004-08-03 23:10 48,128 –a—— c:\windows\system32\dllcache\61883.sys
2009-01-02 14:25 . 2001-08-17 14:55 38,400 –a—— c:\windows\system32\dllcache\8514a.dll
2009-01-02 14:25 . 2001-08-17 13:52 23,552 –a—— c:\windows\system32\dllcache\abp480n5.sys
2009-01-02 14:25 . 2004-08-03 23:00 12,288 –a—— c:\windows\system32\dllcache\4mmdat.sys
2009-01-02 14:25 . 2001-08-17 14:06 11,264 –a—— c:\windows\system32\dllcache\1394vdbg.sys
2008-12-26 12:19 . 2008-12-26 12:19 d——– c:\documents and settings\NetworkService\Application Data\Webroot
2008-12-16 23:06 . 2008-12-16 23:06 d——– c:\program files\Webroot
2008-12-16 23:06 . 2008-12-16 23:06 d——– c:\documents and settings\Compaq_Owner\Application Data\Webroot
2008-12-16 23:06 . 2004-02-11 18:27 102,912 –a—— c:\windows\system32\islzma.dll
2008-12-16 23:06 . 2006-01-25 10:54 78,336 –a—— c:\windows\system32\drivers\ssi.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-04 17:02 ——— d—–w c:\program files\PeerGuardian2
2009-01-02 00:55 ——— d—–w c:\documents and settings\Compaq_Owner\Application Data\OpenOffice.org2
2009-01-01 01:08 9,476 —-a-w c:\documents and settings\Compaq_Owner\Application Data\wklnhst.dat
2008-12-16 15:23 ——— d—–w c:\program files\Mozilla Thunderbird
2008-12-15 18:15 ——— d—–w c:\documents and settings\Compaq_Owner\Application Data\U3
2008-12-12 17:27 3,067,392 —-a-w c:\windows\system32\dllcache\mshtml.dll
2008-11-25 21:24 ——— d—–w c:\documents and settings\All Users\Application Data\DVD Shrink
2008-11-14 19:54 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-07 23:34 ——— d—–w c:\program files\Shockwave.com
2008-11-07 23:33 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2008-11-07 22:26 ——— d—–w c:\documents and settings\Compaq_Owner\Application Data\iWin
2008-10-24 11:10 453,632 —-a-w c:\windows\system32\dllcache\mrxsmb.sys
2008-10-23 13:01 283,648 —-a-w c:\windows\system32\gdi32.dll
2008-10-23 13:01 283,648 —-a-w c:\windows\system32\dllcache\gdi32.dll
2008-10-16 19:13 202,776 —-a-w c:\windows\system32\wuweb.dll
2008-10-16 19:13 202,776 —-a-w c:\windows\system32\dllcache\wuweb.dll
2008-10-16 19:13 1,809,944 —-a-w c:\windows\system32\wuaueng.dll
2008-10-16 19:13 1,809,944 —-a-w c:\windows\system32\dllcache\wuaueng.dll
2008-10-16 19:12 561,688 —-a-w c:\windows\system32\wuapi.dll
2008-10-16 19:12 561,688 —-a-w c:\windows\system32\dllcache\wuapi.dll
2008-10-16 19:12 323,608 —-a-w c:\windows\system32\wucltui.dll
2008-10-16 19:12 323,608 —-a-w c:\windows\system32\dllcache\wucltui.dll
2008-10-16 19:09 92,696 —-a-w c:\windows\system32\dllcache\cdm.dll
2008-10-16 19:09 92,696 —-a-w c:\windows\system32\cdm.dll
2008-10-16 19:09 51,224 —-a-w c:\windows\system32\wuauclt.exe
2008-10-16 19:09 51,224 —-a-w c:\windows\system32\dllcache\wuauclt.exe
2008-10-16 19:09 43,544 —-a-w c:\windows\system32\wups2.dll
2008-10-16 19:08 34,328 —-a-w c:\windows\system32\wups.dll
2008-10-16 19:08 34,328 —-a-w c:\windows\system32\dllcache\wups.dll
2008-10-15 16:57 332,800 —-a-w c:\windows\system32\dllcache\netapi32.dll
2008-10-15 14:18 18,432 —-a-w c:\windows\system32\dllcache\iedw.exe
2008-05-15 21:48 47,360 —-a-w c:\documents and settings\Compaq_Owner\Application Data\pcouffin.sys
2008-01-04 21:57 32 —-a-w c:\documents and settings\All Users\Application Data\ezsid.dat
2008-11-30 14:51 67,696 —-a-w c:\program files\mozilla firefox\components\jar50.dll
2008-11-30 14:51 54,376 —-a-w c:\program files\mozilla firefox\components\jsd3250.dll
2008-11-30 14:51 34,952 —-a-w c:\program files\mozilla firefox\components\myspell.dll
2008-11-30 14:51 46,720 —-a-w c:\program files\mozilla firefox\components\spellchk.dll
2008-11-30 14:51 172,144 —-a-w c:\program files\mozilla firefox\components\xpinstal.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PeerGuardian"="c:\program files\PeerGuardian2\pg2.exe" [2005-09-18 1421824]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2004-08-27 58488]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-02-26 245760]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 253952]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-28 221184]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-12-16 282624]
"SpySweeper"="c:\program files\Webroot\Spy Sweeper\ark.exe" [2006-01-25 3405312]
"SiSPower"="SiSPower.dll" [2005-04-12 c:\windows\system32\SiSPower.dll]
"SMSERIAL"="sm56hlpr.exe" [2005-01-24 c:\windows\sm56hlpr.exe]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 c:\windows\ALCXMNTR.EXE]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /r \??\c:\0autocheck autochk *\0SsiEfr.e\0SsiEfr.e

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Compaq Connections.lnk]
backup=c:\windows\pss\Compaq Connections.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HOTSYNCSHORTCUTNAME.lnk]
backup=c:\windows\pss\HOTSYNCSHORTCUTNAME.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dvd43]
–a—— 2007-11-20 16:40 731136 c:\program files\dvd43\DVD43_Tray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
–a–c— 2004-07-28 01:50 221184 c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
–a—— 2004-10-13 18:24 1694208 c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2006-12-16 09:32 282624 c:\program files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Compaq Connections\\6750491\\Program\\Compaq Connections.exe"=
"c:\\Program Files\\Total War\\Medieval - Total War\\Medieval_TW.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\GigaTribe\\gigatribe.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R0 SSI;SSI;c:\windows\system32\drivers\ssi.sys [2008-12-16 78336]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-04-09 111184]
R4 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-04-09 20560]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d9dcfda2-09e1-11da-b1f9-806d6172696f}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480

*Newly Created Service* - PROCEXP90
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=presario&pf=desktop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=presario&pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=presario&pf=desktop
uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=presario&pf=desktop
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: Add To Compaq Organize… - c:\progra~1\HEWLET~1\COMPAQ~1\bin/module.main/favorites\ie_add_to.html
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Compaq_Owner\Application Data\Mozilla\Firefox\Profiles\k1fomxfs.default\
FF - prefs.js: browser.startup.homepage - www.yahoo.com
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-04 14:09:17
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\TDSSserv.sys]
"imagepath"="\systemroot\system32\drivers\TDSSmaxt.sys"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(568)
c:\windows\system32\WRLogonNTF.dll
.
Completion time: 2009-01-04 14:10:34
ComboFix-quarantined-files.txt 2009-01-04 19:10:15

Pre-Run: 57,452,032,000 bytes free
Post-Run: 57,468,440,576 bytes free

219 — E O F — 2008-12-26 17:33:37

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI